Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44709 |
|
OS Command Injection in CVE-2026-44709 (CVE-2026-44709)
OS command injection in CVE-2026-44709 (CVE-2026-44709). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.7` or later.
|
| CVE-2026-45077 |
|
Unsafe Deserialization in symfony/monolog-bridge (CVE-2026-45077)
vulnerability in symfony/monolog-bridge (CVE-2026-45077). Risk of unauthorized operations or information disclosure. Exploitable via ``allowed_classes``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45075 |
|
Authorization Flaw in symfony/http-kernel (CVE-2026-45075)
vulnerability in symfony/http-kernel (CVE-2026-45075). Data can be tampered with by attackers. Exploitable via ``HEAD``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45074 |
|
Vulnerability in symfony/security-http (CVE-2026-45074)
vulnerability in symfony/security-http (CVE-2026-45074). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45073 |
|
SQL Injection in symfony/cache (CVE-2026-45073)
SQL injection in symfony/cache (CVE-2026-45073). Risk of unauthorized operations or information disclosure. Exploitable via ``AbstractAdapterTrait``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45071 |
|
XXE (XML External Entity) in symfony/dom-crawler (CVE-2026-45071)
vulnerability in symfony/dom-crawler (CVE-2026-45071). Confidential information can be exposed externally. Exploitable via ``Crawler``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45068 |
|
Vulnerability in symfony/mailer (CVE-2026-45068)
vulnerability in symfony/mailer (CVE-2026-45068). Data can be tampered with by attackers. Exploitable via ``MAILER_DSN``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-48064 |
|
Authorization Flaw in CVE-2026-48064 (CVE-2026-48064)
vulnerability in CVE-2026-48064 (CVE-2026-48064). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.9.1` or later.
|
| CVE-2026-47272 |
|
Authentication Bypass in c (CVE-2026-47272)
authentication bypass in c (CVE-2026-47272). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45104 |
|
Vulnerability in osgeo (CVE-2026-45104)
vulnerability in osgeo (CVE-2026-45104). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.6.3` or later.
|
| CVE-2026-45108 |
|
Authorization Flaw in CVE-2026-45108 (CVE-2026-45108)
vulnerability in CVE-2026-45108 (CVE-2026-45108). Confidential information can be exposed externally. Mitigation: upgrade to `3.1.5` or later.
|
| CVE-2026-42197 |
|
Cross-Site Scripting (XSS) in django (CVE-2026-42197)
cross-site scripting in django (CVE-2026-42197). Confidential information can be exposed externally. Exploitable via ``ParticipationAdmin``.
|
| CVE-2026-44982 |
|
Vulnerability in github.com/crowdsecurity/crowdsec (CVE-2026-44982)
vulnerability in github.com/crowdsecurity/crowdsec (CVE-2026-44982). Risk of unauthorized operations or information disclosure. Exploitable via ``REQUEST_BODY``. Mitigation: upgrade to `1.7.8` or later.
|
| CVE-2026-44726 |
|
Vulnerability in deno (CVE-2026-44726)
vulnerability in deno (CVE-2026-44726). Confidential information can be exposed externally. Exploitable via `POST /v1/charge`. Mitigation: upgrade to `2.7.8` or later.
|
| CVE-2026-4868 |
|
Vulnerability in gitlab (CVE-2026-4868)
vulnerability in gitlab (CVE-2026-4868). Confidential information can be exposed externally. Mitigation: upgrade to `18.10.7, 18.11.4, 19.0.2` or later.
|
| CVE-2026-5509 |
|
Vulnerability in tp-link (CVE-2026-5509)
vulnerability in tp-link (CVE-2026-5509). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69600 |
|
Command Injection in CVE-2025-69600 (CVE-2025-69600)
command injection in CVE-2025-69600 (CVE-2025-69600). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38807 |
|
Vulnerability in CVE-2026-38807 (CVE-2026-38807)
vulnerability in CVE-2026-38807 (CVE-2026-38807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48149 |
|
Cross-Site Scripting (XSS) in CVE-2026-48149 (CVE-2026-48149)
cross-site scripting in CVE-2026-48149 (CVE-2026-48149). Confidential information can be exposed externally. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-48151 |
|
Vulnerability in @budibase/server (CVE-2026-48151)
vulnerability in @budibase/server (CVE-2026-48151). Data can be tampered with by attackers. Exploitable via `POST /api/webhooks/schema/`. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-48152 |
|
Authorization Flaw in @budibase/server (CVE-2026-48152)
vulnerability in @budibase/server (CVE-2026-48152). Confidential information can be exposed externally. Exploitable via `GET /api/datasources/`. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-48153 |
|
SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-48153)
SSRF in @budibase/server (CVE-2026-48153). Confidential information can be exposed externally. Exploitable via ``fetchToken``. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-46427 |
|
Information Disclosure in CVE-2026-46427 (CVE-2026-46427)
vulnerability in CVE-2026-46427 (CVE-2026-46427). Confidential information can be exposed externally. Exploitable via `GET /api/datasources/`. Mitigation: upgrade to `3.38.3` or later.
|
| CVE-2026-48146 |
|
SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-48146)
SSRF in @budibase/server (CVE-2026-48146). Confidential information can be exposed externally. Exploitable via ``fetchWithBlacklist``. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-44378 |
|
Vulnerability in c (CVE-2026-44378)
vulnerability in c (CVE-2026-44378). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.12.0` or later.
|
| CVE-2026-44460 |
|
Information Disclosure in CVE-2026-44460 (CVE-2026-44460)
vulnerability in CVE-2026-44460 (CVE-2026-44460). Confidential information can be exposed externally. Mitigation: upgrade to `3.12.0` or later.
|
| CVE-2026-45617 |
|
Vulnerability in liquidjs (CVE-2026-45617)
vulnerability in liquidjs (CVE-2026-45617). Risk of unauthorized operations or information disclosure. Exploitable via ``strip_html``. Mitigation: upgrade to `10.26.0` or later.
|
| CVE-2026-45357 |
|
Vulnerability in liquidjs (CVE-2026-45357)
vulnerability in liquidjs (CVE-2026-45357). Risk of unauthorized operations or information disclosure. Exploitable via ``date``.
|
| CVE-2026-45260 |
|
Vulnerability in pimcore/pimcore (CVE-2026-45260)
vulnerability in pimcore/pimcore (CVE-2026-45260). Data can be tampered with by attackers. Exploitable via ``MOVE``. Mitigation: upgrade to `11.5.17` or later.
|
| CVE-2026-42790 |
|
Vulnerability in erlang (CVE-2026-42790)
vulnerability in erlang (CVE-2026-42790). Confidential information can be exposed externally.
|
| CVE-2026-42083 |
|
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
|
| CVE-2026-42459 |
|
Vulnerability in github.com/free5gc/udm (CVE-2026-42459)
vulnerability in github.com/free5gc/udm (CVE-2026-42459). Confidential information can be exposed externally. Exploitable via ``supi``.
|
| CVE-2026-38945 |
|
Command Injection in CVE-2026-38945 (CVE-2026-38945)
command injection in CVE-2026-38945 (CVE-2026-38945). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45162 |
|
Unsafe Deserialization in pimcore/pimcore (CVE-2026-45162)
vulnerability in pimcore/pimcore (CVE-2026-45162). Successful exploitation can lead to full system takeover. Exploitable via ``allowed_classes``. Mitigation: upgrade to `2026.1.3` or later.
|
| CVE-2026-46031 |
|
Vulnerability in linux (CVE-2026-46031)
vulnerability in linux (CVE-2026-46031). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45998 |
|
Use-After-Free in linux (CVE-2026-45998)
vulnerability in linux (CVE-2026-45998). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45991 |
|
Out-of-Bounds Write in linux (CVE-2026-45991)
out-of-bounds write in linux (CVE-2026-45991). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45989 |
|
Use-After-Free in linux (CVE-2026-45989)
vulnerability in linux (CVE-2026-45989). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45980 |
|
Use-After-Free in linux (CVE-2026-45980)
vulnerability in linux (CVE-2026-45980). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45955 |
|
Vulnerability in linux (CVE-2026-45955)
vulnerability in linux (CVE-2026-45955). Data can be tampered with by attackers.
|
| CVE-2026-45970 |
|
Use-After-Free in linux (CVE-2026-45970)
vulnerability in linux (CVE-2026-45970). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45957 |
|
Out-of-Bounds Read in c (CVE-2026-45957)
vulnerability in c (CVE-2026-45957). Confidential information can be exposed externally.
|
| CVE-2026-45951 |
|
Use-After-Free in linux (CVE-2026-45951)
vulnerability in linux (CVE-2026-45951). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45956 |
|
Use-After-Free in linux (CVE-2026-45956)
vulnerability in linux (CVE-2026-45956). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45959 |
|
Vulnerability in linux (CVE-2026-45959)
vulnerability in linux (CVE-2026-45959). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45929 |
|
Use-After-Free in linux (CVE-2026-45929)
vulnerability in linux (CVE-2026-45929). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45933 |
|
Vulnerability in linux (CVE-2026-45933)
vulnerability in linux (CVE-2026-45933). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45935 |
|
Out-of-Bounds Read in linux (CVE-2026-45935)
vulnerability in linux (CVE-2026-45935). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45936 |
|
Use-After-Free in linux (CVE-2026-45936)
vulnerability in linux (CVE-2026-45936). Successful exploitation can lead to full system takeover. Exploitable via ``devm_``.
|
| CVE-2026-45938 |
|
Use-After-Free in linux (CVE-2026-45938)
vulnerability in linux (CVE-2026-45938). Successful exploitation can lead to full system takeover. Exploitable via ``devm_``.
|